metamaskk[.]myftp[.]org
“The Ultimate Crypto Wallet for DeFi, Web3 Apps, and NFTs | MetaMask”
This domain, metamaskk.myftp.org, is flagged as a brand impersonation threat designed to deceive users of the Ledger cryptocurrency wallet. Analysis indicates the site presents itself as MetaMask, a popular crypto wallet, with the page title "The Ultimate Crypto Wallet for DeFi, Web3 Apps, and NFTs | MetaMask." The intent appears to be credential harvesting or distribution of malicious payloads, likely targeting users seeking Ledger integration or support. No crypto drainer kit signatures were explicitly identified, but the domain structure and content suggest a focus on phishing for sensitive wallet information.
Technical indicators reveal the domain was registered on February 21, 2026, through Vercer Inc., and resolves to the IP address 216.198.79.1, hosted on Amazon.com, Inc. infrastructure (AS16509). VirusTotal reports 18 out of 95 security vendors flagging the domain as malicious. The domain lacks an SSL certificate, a common red flag for phishing sites. It appears on one security blocklist and was blocked by PhishDestroy. Google Safe Browsing status is not explicitly provided, but the combination of low vendor detection and absence of SSL suggests a lower-profile campaign.
As of the latest assessment, metamaskk.myftp.org has been taken offline, reducing immediate risk to users. However, the infrastructure (Vercel, Amazon hosting) remains accessible, and similar domains may emerge. Users are advised to verify wallet-related communications through official channels only. Organizations should monitor for domains registered under Vercel or similar services with cryptocurrency-related keywords, particularly those impersonating MetaMask or Ledger. Blocking the IP 216.198.79.1 and domains with the seed "f579fe" in their structure may mitigate residual risk.
Threat Response Pipeline
Public Blocklist Status
Forensic Intelligence
VirusTotal Analysis
Archived Evidence
Evidence & External Reports
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive